competition-ios-runtime

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for a CTF/mobile-reversing purpose, and the visible install provenance is not obviously malicious; however, it gives an AI agent high-risk offensive iOS runtime-analysis capabilities, including secret extraction, SSL pinning bypass, and replay of accepted requests. The main concern is exploit capability and sensitive-data handling, not confirmed malware or overt credential exfiltration.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Jul 30, 2026, 12:52 PM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Fai-fullstack-delivery-workflow%2Fcompetition-ios-runtime%2F@d42bbb235ed5017145e6400f5d422e5e5ef6525a3d76150803a62982769739c3
Security Audit — socket — competition-ios-runtime